FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Description The article describes how to alter the default login-attempt-limit and login-block-time for SSL VPN users.
Solution The default login-attempt-limit for SSL VPN users is 2 and the login-block-time is 60 seconds. This indicates if user enters incorrect username/password combinations continuously twice, the firewall will block attempts and prompt with message as 'Too many bad attempts. Please try again in few minutes'. Now, user has to wait for 60 seconds to try login again .
To increase or alter the value, configure the desired values using CLI as below.
The same as above in writing.
#config vpn ssl settings set login-attempt-limit x <----- Replace number of attempt to allow in place of x. set login-block-time y <----- Replace number of seconds to block attempt in place of y. end
The above config will help in preventing brute force attacks through SSL VPN.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.